Back to home

HIPAA

The US standard for protecting health information, for covered entities and their vendors.

Overview

The Health Insurance Portability and Accountability Act (HIPAA) sets requirements for protecting Protected Health Information (PHI) in the United States, applying both to covered entities (healthcare providers, plans) and their business associates, including most health tech vendors.

Why it matters

If your product touches PHI for a US healthcare customer, they'll require a signed Business Associate Agreement (BAA) and evidence of a HIPAA-aligned security program before they'll sign a contract. HIPAA violations carry both regulatory and reputational risk.

How Sense Six Cyber helps

  • Determine business associate status and applicable obligations
  • Conduct a HIPAA Security Rule risk assessment
  • Build required administrative, physical, and technical safeguards
  • Draft Business Associate Agreements
  • Prepare for customer HIPAA due diligence and questionnaires

Ideal for

Health tech companies or vendors processing PHI on behalf of US healthcare customers.